SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions accept a user-controlled input that specifies a link to an external site and uses that link in a redirect which leads to Open redirection vulnerability.
2022-05-13T20:15:07.950
2024-11-21T06:41:16.927
Modified
CVSSv3.1: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:N
8.6
4.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | sonicwall | sma_6200_firmware | 12.4.0 | Yes |
| Operating System | sonicwall | sma_6200_firmware | 12.4.1 | Yes |
| Hardware | sonicwall | sma_6200 | - | No |
| Operating System | sonicwall | sma_6210_firmware | 12.4.0 | Yes |
| Operating System | sonicwall | sma_6210_firmware | 12.4.1 | Yes |
| Hardware | sonicwall | sma_6210 | - | No |
| Operating System | sonicwall | sma_7200_firmware | 12.4.0 | Yes |
| Operating System | sonicwall | sma_7200_firmware | 12.4.1 | Yes |
| Hardware | sonicwall | sma_7200 | - | No |
| Operating System | sonicwall | sma_7210_firmware | 12.4.0 | Yes |
| Operating System | sonicwall | sma_7210_firmware | 12.4.1 | Yes |
| Hardware | sonicwall | sma_7210 | - | No |
| Operating System | sonicwall | sma_8000v_firmware | 12.4.0 | Yes |
| Operating System | sonicwall | sma_8000v_firmware | 12.4.1 | Yes |
| Hardware | sonicwall | sma_8000v | - | No |